Export limit exceeded: 403995 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 403995 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (403995 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-107831 1 Banq 1 Jivejdon 2026-10-09 4.3 Medium
Jivejdon through 5.0 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing actions by abusing GET endpoints lacking anti-CSRF tokens. Attackers can lure authenticated users to crafted links targeting /account/protected/delAll, /account/protected/sub/delSub, or /message/updateAction to delete private messages and subscriptions or rename threads.
CVE-2026-107715 1 Sparklemotion 1 Mechanize 2026-10-09 6.8 Medium
The Mechanize library is used for automating interaction with websites. Prior to 2.14.1, Mechanize sends caller-supplied credential headers to a different host after an HTTP redirect. Mechanize#request_headers= is reapplied by Mechanize::HTTP::Agent#request_add_headers even after Mechanize::HTTP::Agent#response_redirect strips per-request headers, and the protected header lists omit Proxy-Authorization and Cookie2. An attacker who controls a redirect target can capture bearer tokens or session cookies supplied through request_headers= or the per-request headers argument, while Mechanize#cookie_jar and Mechanize::HTTP::AuthStore are not affected. This issue is fixed in version 2.14.1.
CVE-2026-105827 1 Imagemagick 1 Imagemagick 2026-10-09 5.3 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105826 1 Imagemagick 1 Imagemagick 2026-10-09 5.3 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105825 1 Imagemagick 1 Imagemagick 2026-10-09 5.3 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105824 1 Imagemagick 1 Imagemagick 2026-10-09 5.9 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105823 1 Imagemagick 1 Imagemagick 2026-10-09 4.0 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105405 1 Imagemagick 1 Imagemagick 2026-10-09 5.9 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105404 1 Imagemagick 1 Imagemagick 2026-10-09 5.3 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105403 1 Imagemagick 1 Imagemagick 2026-10-09 6.2 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105402 1 Imagemagick 1 Imagemagick 2026-10-09 5.3 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105401 1 Imagemagick 1 Imagemagick 2026-10-09 5.3 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-11936 1 Ibm 4 Security Verify Access, Security Verify Access Container, Verify Identity Access and 1 more 2026-10-09 4.9 Medium
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 local management interface in certain configurations is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2026-105400 1 Imagemagick 1 Imagemagick 2026-10-09 3.3 Low
This CVE ID has been rejected as a duplicate.
CVE-2026-105399 1 Imagemagick 1 Imagemagick 2026-10-09 5.3 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105398 1 Imagemagick 1 Imagemagick 2026-10-09 5.1 Medium
This CVE ID has been rejected as a duplicate.
CVE-2026-105275 1 Satel 1 Satel Netco Design 2026-10-09 4.3 Medium
Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data import functionality. An authenticated user with Viewer privileges could access file paths outside the intended directory and use observable application responses to determine whether files exist on the host system.
CVE-2026-104628 1 Satel 1 Satel Netco Design 2026-10-09 6.5 Medium
Satel Netco Design versions prior to v2.1.7 contains an inefficient regular expression complexity vulnerability. An authenticated user with Viewer privileges could submit crafted search input that causes excessive processing, potentially degrading the availability of the application.
CVE-2026-101024 1 Satel 1 Satel Netco Design 2026-10-09 8.8 High
Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data export functionality. An authenticated user with Viewer privileges could write attacker influenced content to file system locations accessible to the application service. Successful exploitation could result in unauthorized file creation or modification and, under certain conditions, arbitrary code execution.
CVE-2022-2946 3 Debian, Fedoraproject, Vim 3 Debian Linux, Fedora, Vim 2026-10-09 7.8 High
Use After Free in GitHub repository vim/vim prior to 9.0.0246.